How to Redact a PDF: A Real Guide to Permanently Removing Sensitive Information
6 min read
When you cover a name, a national ID number, or bank account details on a PDF with a black box, do you assume that information is truly gone? Most people do — and that assumption turns into a serious security hole the moment the file gets shared. In this guide, I'll walk through how to properly redact (censor) a PDF, why simply "covering it up" isn't enough, and how to set up a genuinely secure step-by-step process.
What do we actually mean by redaction?
Redaction means permanently and irreversibly removing sensitive information from a document. From court filings to employment contracts, medical records to financial reports, many documents need certain sections hidden before they're shared. The problem is that "hiding" and "deleting" are not the same thing. Drawing a black rectangle over a name in a PDF editor often just adds a visual layer — the text underneath continues to exist, unchanged, in the PDF's internal structure.
The most common mistake: the "cover with a box" trap
PDF files are, in effect, layered structures made up of text, images, and vector objects. When you draw a black box over an area in a word processor or a basic PDF viewer, you're simply adding a new object on top — the original text object beneath it is not deleted. In that situation, anyone can:
- open the PDF in a text editor (or sometimes just with a simple copy-paste) and see the text underneath,
- drag the box away and remove it,
- or still find that text in the file's search/indexing data.
This is a mistake that has played out in the real world time and again: there are well-publicized cases of government agencies, law firms, and companies sharing "censored" documents where names, signatures, and account numbers turned out to be recoverable from under the black box. The root cause is always the same — the cover-up stayed purely visual, and the content layer itself was never touched.
The correct method: rasterize and flatten
The core logic of secure redaction is this: first, truly remove the sensitive area from the document, then convert the page into an image (rasterize), turning it into a single flat layer. After this process, the page no longer contains individually selectable text objects — it behaves like a photograph. There can be no "hidden" text layer beneath the box, because that layer is never reconstructed in the first place.
This is where the approach differs from simple "box drawing": the process doesn't just change the appearance, it eliminates the underlying data structure of the page itself. As a result, when the file is searched, when text is selected, or when the file is inspected with another tool, the covered information can no longer be reached.
Step by step: safely removing sensitive information from a PDF
1. Identify the document and the areas to redact. Start by reviewing the entire document from beginning to end. Don't just check the visible body text — also check headers/footers, footnotes, table cells, and even text embedded inside images. Making a list of items like ID numbers, signatures, addresses, and bank details reduces the risk of missing something.
2. Consider metadata and embedded data too. Keep in mind that PDF files can carry metadata beyond the visible pages — author name, edit history, comments/notes, and similar fields. When redacting, pay attention not just to page content but to these additional information fields as well.
3. Open the tool and upload your file. Upload your document to the PDF redaction tool. Your file is only used for the duration of processing; with sensitive documents, it matters to know how the file is handled after processing, so it's worth checking the retention policy of whatever tool you use.
4. Mark the areas to hide. Using your cursor, select the areas covering the sensitive text, numbers, or images on the page. Be a bit generous with the selected area — rather than aligning exactly to the edges of the text, extending the selection by a few extra pixels prevents edge leaks (like the tip of a letter still showing).
5. Check every page individually. In multi-page documents, the same piece of information (like an ID number) can repeat in more than one place. Signature pages, appendices, and footnotes in contracts are especially easy to overlook — go through each page separately.
6. Run the process and let the rasterize-flatten step complete. At this stage, the tool removes the actual content underneath the areas you marked and converts the page into a flattened image. Once finished, the page no longer contains separate, selectable/copyable text objects.
7. Verify the result. In the downloaded file, hover over the redacted areas and try selecting text — nothing should be selectable. Search for that word or number with Ctrl+F — it should return no results. If possible, open the file in a different viewer and check again.
8. Review the file name and metadata before sharing. Sometimes sensitive information lingers in the file name itself (e.g., "John_Smith_medical_report.pdf"). Don't forget to neutralize the file name before sharing as well.
Common mistakes
- Checking only the visible pages and skipping appendices. In long contracts and technical documents, appendices are often overlooked.
- Marking areas without zooming in. Small fonts may look fine at page view, but if your selection shifts slightly, part of a letter can be left uncovered.
- Missing the fact that the same information appears elsewhere in the document. Repeated ID or reference numbers in headers/footers are especially easy to forget.
- Sharing the file without testing it after redaction. The text-selection and search test takes two minutes but prevents an irreversible mistake.
- Leaving the original, unredacted file in the same folder and accidentally sharing that one instead. Name the two files clearly so they're easy to tell apart.
When should you use it?
Any document going to a third party that contains identity information, financial data, or personal details — employment contracts, lease agreements, court documents, medical reports, bank statements, resumes, internal correspondence — should be considered for redaction. This is especially true when the document is headed to an institution, a journalist, a business partner, or a public platform: you need a version that is genuinely removed, not just "apparently covered."
Conclusion
Hiding sensitive information in a PDF is not as simple as drawing a shape over it. The difference between visually covering something and actually removing the content determines whether a document is truly secure or just deceptively appears to be. A redaction process built on rasterize-flatten logic removes the underlying data along with the covered area, eliminating that risk entirely. If you follow the steps above and always test the result before sharing, you protect both yourself and the people named in the document from an unnecessary data leak.
Frequently Asked Questions
What's the difference between covering something with a black box and using a proper redaction tool?
A black box is usually just a new visual layer added on top of the page; the original text underneath stays exactly as it was inside the PDF and can resurface through text selection or copying. A redaction process built on rasterize-flatten logic first removes the actual content in that area, then converts the page into a single flattened image. That way, no extractable text layer remains beneath the covered area.
How can I be sure the file is actually safe after redaction?
Once processing is complete, open the downloaded file, hover over the area you covered, and try to select text with your mouse — nothing should be selectable. Then search for the hidden word or number with Ctrl+F — it should return no results. Repeating these two simple tests in a different PDF viewer gives you extra assurance.
Can you redact a scanned (image-based) PDF too?
Yes. Since a scanned document's page is already an image, marking the sensitive area and removing that region is actually simpler than with a digitally-typed PDF, because there's no separate text layer underneath to extract. Still, it's worth zooming in to confirm your marked area fully covers the text with no overflow at the edges.
Try this out right away with PDF Redaksiyon.
Try PDF Redaksiyon